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Sir: 

This is a R^ply Brief responding to the Examiner's Answer 
mailed December 27, 2007. Additionally, Appellant notes that 
a Request for Oral Hearing was made on March 13, 2006, in 
connection with present Appeal, and the oral hearing fee was 
previously paid. Appellant, hereby, renews and reiterates 
that Request for Oral Hearing, 
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FEB 2 7 20D7 

Please consider the present Reply Brief in combination with 
the Appeal Briefs and other Reply Briefs filed by Appellant in 
connection with present Appeal, Appellant comments as follows 
with respect to the Examiner's Answer dated December 27, 2006 
(the ''Examiner's Answer''): 



la item (7) of the Examiner's Answer, entitled Grouping Of 
Claims, the Examiner states that the brief includes a 
statement that claims 4, 24 and 26 do not stand or fall 
together and provides reasons. Appellant respectfully notes 
that Appellant provided reasons for the patentability of 
claims 1, 1^, 4, 24 and 26, and not merely claims 4, 24 and 
26. Appellant respectfully requests that the all of the 
individually argued claims be considered in the present 
Appeal . 



Further, page 4 of the Examiner's Answer, stated, in part: 



Iieon discloses the sysiiem coEnaponenbs as per the prior 
0£±±<i& Action except for the removah>ie authorization 
device. However, Leon does disclose as per Col, 37, 
lines 48 - 50, that the Secure Meter Device (SMD) can 
further include an input interface circuit that 
couples to an input element. The input element can be 
a switch, a push button, a key, or the like. The 
Examiner submits that teaching of the use of an 
external input element provides the motivation/bridge 
to incorporate the use of a dongle and/or 
cryptographic key stored on a token as taught by the 
second reference Vuin the prior 103 Office Action, 
[emphasis added by Appellant] 
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Appellant respectfully disagrees with the above statements 
from the Kxaminer's Answeir. 

First, among other things. Appellant respectfully disagrees 
with the statement alleging that "Leon discloses the system 
components as per the prior Office Action except for the 
removable authorization device''. Among other limitations of 
Appellant's claims, Leon does not disclose a securitiy mcdijle 
or a removable authorization device, A sec^ritry module (as 
recited in Appellant's claims) and a secure metering device or 
SMD (as disclosed in Leon) are not comparable. Rather, 
Appellant's claimed security module "serves for checking the 
authorization and can prevent xnitxalxzation without 
authorization." See, the Abstract of the instant application, 
the fourth full sentence. Appellant's claims similarly define 
the claimed security module. For example. Appellant's claim 1 
recites, among other limitations: 

said security module being programmed to check whether 
authorization is present and for preventing- an 
initialization of said mailing machine without 
authorization . [emphasis added by Appellant] 

Similarly, Appellant^ s independent claim 18 recites, among 
other limitations: 

authorizing an initialization with an authorization 
device and checking authorization with a security 
module , in order to prevent initialization without 
au thori za tion ; [emphasis added by Appellant] 
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However, contrary to Appellant's claimed security module, an 
SMD, as disclosed in Leon, is already inxtialized b y a Cr^to- 
^^^^o^ic , prior to checking the authorizations. This can be 
seen from col, 8 of Leon, line 63 - col. 9, line 19, which 
states : 



A Crypto-Of f icer initializes the SMD at the factory 

(i»e,, after the metering device has been 
manufactured) . The Crypto-Of f icer role is available at 
the factory, before the SMD is sealed in its tamper- 
evident enclosure. The SMD validates the Crypto- 
Of f icer when the Crypto-Of f icer installs a FIT (field 
initialization transaction) flag that is located on 
the SMD. The SMD perforins the Initialization service 
after the flag has been installed. The Initialization 
service causes the SMD to generate a pair of public 
and private Iceys, export the public key, and load a 
Provider X.509 certificate that includes the 
provider's public key. The Crypto-Of f icer obtains and 
provides the Provider X.509 certificate to the SMD and 
archives the SMD's public key. After initializincy the 
SMD, the Crypto-Of f icer removes the flag and closes 
the tamper-evident cover , 



The SMD supports the provider role i>y providing the 
following services: Registration, Funding, Audit, and 
Withdrawal* These services are described in detail 
below. Whenever one of these services Is recyuested^ 
the SMD validates that the requester is an authorized 
provider . This is achieved by using the provider's 
public key to validate the signature on the service 
request that has been signed using the provider's 
private key. The provider's public key is retrieved 
from the Provider X,5d9 certificate that is loaded by 
the Crypto-Of ficer during initialization, [emphasis 
added by Appellant] 



As can be seen from the foregoing, in I^eon, initialization is 
con^leted prior to checking any authorizations. As such, 
among other limitations of Appellant's claims, Leon fails to 
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teach or suggest Appellant's particularly claimGd securlizy 
module which checks authorization, in order to prevent 
initialization without authorization . The Vu reference does 
not cure the above-described deficiency in the teachings of 
Leon, 



In addition to the remarks made above. Appellant incorporates 
herein by reference, and reiterates, the further remarks made 
in the Supplemental i^peal Brief, discussing how neither of 
the cit ed references , U. S. Patent No, 6,424,954 to Leon 
"(LEON") or U. Patent No. 6, 557, 104 to Vu et al ( "VU*' ) ^ 

teach or suggest, among other limitations: {!> "a removable 
authorization device operationally connected to the mailing 
machine and configured to be interrogated by the mailing 
machine; and (2) the security module programmed to check 
whether authorization is present and for preventing an 
initialization of the mailing machine without authorization as 
recited in independent claim 1 of the instant application or 
the similar limitations recited in Appellant's independent 
method claim 18, 

As neither of the LEON or VU references teach or suggest, 
among other limitations of Appellant's claims, items' (1) and 
(2) above. Appellant's claims are believed to be patentable 
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over the LEON .and VU references, taken alone, or in 
combination. 

Further, Appellant maintains its belief that, absent 
impermissible hindsight reconstruction, there is no motivation 
in either LEON or VXJ to combine those references to arrive at 
Appellant's claimed invention. More particularly^ there is no 
motivation in LEON or VU to add a method or apparatus for 
secure processing of cryptographic keys, as taught in VU, to 
the postal system of leoN- 

Specifically addressing the portion of LEON cited on page 6 of 
the Examiner's Answer, col, 37, lines 48 - 50 of LEON do not 
provide motivation to provide, among other limitations of 
Appellant's claims, a removah>le authorization device, 
authorization from which is necessary for initialization of 
the mailing machine (or initialization of any other device) , 
as required by Appellant's claims 1 and 18, Initialization, 
in the context of claims 1 and 18, is explained in the 
specification of the instant application. For example, page 5 
of the instant application, line 8 - page 6, line 2, describes 
initialization as follows: 

^'^i'tiali nation is understood as meaning a routine for ' 
the input of initialization data taking place on one 
occasion at the single point of entry of the 
destination country before the machine is put into 
operation . For this purpose, a means of authorization 
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is brought into operative connection with the mailing 
machine and is designed as an easily exchangeable 
electronic hardware unit (dongle or chip card) , The 
latter is connected to the mailing machine either 
directly or indirectly via a data source, for example 
a personal computer PC* The mailing machine, for 
example a franking machine, has an unremovable program 
memory witJi an initialization program and. a postal 
security module {postal security device or secure 
accounting device) , which is designed as a means of 
checking the authorization of the input of 
initialization data. The latter takes place, when 
there is authorization, directly by using the keyboard 
of the franking machine or indirectly via the PC or 
laptop or from a data center into the meter or 
security module. The means of authorization, i.e., 
the authorization device^ is brought into operative, 
connection with the meter via interfaces of the PC or 
the machine. [emphasis added by Appellant] 

For example, page 5 of the instant application, lines 5 - 14, 
states : 



The object of the present invention is to provide a 
mailing machine which overcomes the above-noted 
deficiencies and disadvantages of the prior art 
devices and methods of this general kind, and which is 
provided with a ROM module with an initialization 
program ^ initialization data being introduced in a 
secure manner into the mailing machine via an 
externally accessible inter-face, so that unauthorized 
initializing is prevented . It is further intended that 
a secure method will manage without exchanging the ROM 
module and permit authorized initialization, 
[emphasis added by Appellant] 



The section of LEON cited in the Examiner's Answer as 
motivating a combination of LEON with w to, allegedly, teach 
Appellant's claimed invention has absolutely nothing to do 
*ith initializing the mailing machine, as does the removable 
authorization device of Appellant's claims. Rather, Col. 37 
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of LEON, lines 48 - 50, read in the entire context of lines 47 
- 60, reads as follows: 



Referring back to FIG. 2A, SMD 150 can further include 
an input interface circuit 236 that couples via signal 
line 237 to an input element 238. Input element 238 
can be a switch, a push button, a key, or the like. 
When input element: 238 is activated (i.e., by pushing 
on a print control key) ^ SMD ISO of metering device 
110a performs the Indicium trangaction . SMD 150 
generates an indicium having a predetermined value and 
directs printer 152 to dispense the indicium , SMD 150 
updates its revenue registers when the indicium is 
generated . SMD 150 generates the indicium */hen 
recces ted and as long as the funds in the revenue 
registers are sufficient to cover the indicium value. 
Otherwise, the metering device can indicate a failed 
Indicium transaction via, for example, a blinking 
light emitting diode (LED) . [emphasis added by 
Appellant] 



As such, the input element 238 of LEON, cited by the Examiner 
as the motivation to combine LEON with an external 
"authorization device" as claimed by Applicants, does not 
relate to providing an authorization, based upon which the 
'^^alllwg machine is initialized , as required by i^plicants • 
claims, but, rather, is merely a push button or key used for 
printing the indicium Ci.e>, the postage slip) . Rather, LEON 
addresses init:ialization of the device in LEON in col. 13, 
lines 22 60, as follows: 



Initialization transaction: An Initialization 
transaction prepares the SMD for operation. The 

following is a specific implementation of the 
Initialization transaction, and other implementations 
are available. 
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FIG. 5B shov;s a flow diagram of an embodiment of the 
Initialization transaction- At a step 520, the SMD is 
prepared for the Initialization transaction. This 
preparation can comprise installing a FIT flag located 
on the SMD. The Crypto-Of f icer then, via a host PC, 
sends the SMD an initialization request message that 
includes the Provider X.509 certificate and the device 
ID number, at a step 522, This request message is 
signed using the provider's private key. The SMD 
receives and validates the request message^ at a step 
524. 



The SMD accepts a request to perform an Initialization 
transaction if it is in an Uninitialized or 
Initialized state. This determination is performed at 
a step 526. If the SMD receives a request to perform 
an Initialisation transaction and the FIT flag is not 
installed or if the SMD 'is not in the Uninitialized or 
Initialized state, the SMD ignores the request and the 
transaction terminates. The validation of the request 
message includes verification of the signature in the 
request message using the provider's public key from 
the Provider X.509 certificate, at a step 528. If the 
signature is invalid, the SMD sends an error message, 
at a step 530, and the transaction terminates. 

If the signature is valid, the SMD saves the Provider 
X.SOB certificate provided in the request message, at 
a step 532. The DSA (digital signature algorithm) 
parameters p, q, and r are then loaded into the SMD, 
at a step 534. The SlyiD uses these parameters to 
generate a pair of public and provide keys, at a step 
536- The SMD retains the private key in secrecy and 
exports the public key. The SMD sends the host PC a 
signed message that includes the SMD's public key, at 
a step 538. This message is signed using the SMD*s 
private key and can be verified by the host PC using 
the SMD's public key that is included in the message. 
The SMD then transitions to the Initialized state, at 
a step 540. Befozre an initialized SMD leaves the 
factory, the Czrypto-Of f icer removes the FIT flag and 
seals the taraper-evident enclosiijce, at a step 542* 
[emphasis added by Appellant] 



IiEON teaches that before an initialized SMD (one containing 
the key) leaves the factory, the Crypto-Of f icer removes the 
FIT flag and seals the tamper-evident enclosure, at a step 
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542. In Leon, nothing further can ever be '^removably 
attached" to provide authorization for initialization. As 
such, LEON fails to teach or suggest, or provide any 
motivation at all, for a removable authorization device, the 
point of which is to prevent an initialization of the mailing 
machine without authorization ^ as clairaed by Appellant . The 
input element 238 of I^ON has nothing to do with authorizing 
initialization (i.e., as defined in the instant specification) 
of the postal machine of ueON, as is required of the removable 
authorization device of Appellant's claims, but merely is used 
to print the frank, and thus, cannot be said to provide the 
motivation alleged by the Examiner, 



Rather, the LEON reference describes a "funding transaction" 

which is performed when the indicium register is zero (i.e., 
no more funds are available for printing an indicium) which is 
allegedly closer to Appellant's claimed initialization. For 
example, col, 37, lines 32 - 39 of LEON discloses a '^funding 
transaction" described as follows: 



"In the stand-alone mode, the metering device is 
capable of printing as many indicia (i.e,, of a 
predetermined value) as allowed by the funds stored in 
the SMD. Once the SMD has expended the funds stored 
in its revenue registers^ i t can be loaded with 
additional funds by perforiaing another Ftmding^ 
"t^ransaction . The metering device caji then be re- 
coupled to the host PC for this Funding transaction, 
and disconnected again after the Ending transaction . " 
[emphasis added by Appellant] 
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Although described in connection with the embodiment that uses 
the input element 238, cited by the Examiner, the input 
element 238 of LEON is not used in the funding transaction. 
Rather, the teaching in col. 37, lines 48 - 50 of LEON, rsad 
in its entire context, merely provides a motivation for 
providing a push button or key to print franJcs (i.e. 
indiaixam) , which must only neceagarily occur a^tex- a funding 
transac tion (ar^endo, "initialization") has been completed . 



As such. Appellant respectfully traverses the allegation in 
the Examiner's Answer that there is motivation in LEON for 
Appellant ^s particularly claimed authorization' device. 



Further, on page 7 of the Examiner's Answer, it is alleged 
that: 



The Appellant further argues that Leon is initializing 
a security module, not the mailing machine as recited 
in the instant claims. The Examiner submits that the 
mailing machine has a security module/section that 
must be initialized before it can function. The kind 
or type of equipment/machine that is initialized does 
not render an invention original, unique or non- 
obvious . The method incorpor-ated to initialize a 
piece of equipment/machine is what is being presented 
and addressed in the prior Office Action. [emphasis 
added by Appellant] 



However, as stated above. Appellant maintains that the LEON 
reference does not teach or suggest an authorization device, 
that is required for initiaXizating a device. The printing of 
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an "indicium" (i.e., frank or mailing slip) of LKON does not 
entail "initialization", as claimed by Appellant. 

Further, on page B of the Examiner's Answer, it is stated 
that: 

• 

In reference to the Appellant's statement that, . . 
-there is no clear and. particular teaching or 
suggestion in Leon to incorporate the features of Vu * 
, the Examiner submits that Leon's [sic] discloses 
the use of an input element that includes a switch, a 
key or the like. Col. 37, liners 34-48 [sic] . Vu 
teaches about a type of key that could be used. 

As discussed above. Appellant respectfully disagrees that I^ON 
provides the alleged motivation. The input element of LEON is 
unrelated to ini tiali za tion of the mailing machine (i.e., or 
any other device) , as required t>y Appellant»s claims 1 and 18, 

but is merely used to print out the "indiciiim" (i.e,, printing 
franks after a funding transAction/"initialization" has been 
completed) / As such. Appellant believes that I^ON truly fails 
to provide the alleged motivation for combining LEON with VD, 
to disclose Appellant's invention of claims 1 and 18. 

Appellant further realleges and incorporates herein the 
arguments made in its Appeal Brief dated November 4, 2005, 
relating to claims 1, IS, 4, 24 and 26. 
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Based on the above given arguments the honorable Board is 
therefore respectfully urged to reverse the final rejection of 
the Primary Examiner. 

Please charge any additional fees that might be due with 
respect to Sections 1.16 and 1.17 to the Deposit Account of 
Lerner Greenberg Sterner LLP, No. 12-1099. 

Respectfully submitted. 



February 27, 2007 

Lerner Greenberg Sterner LLP 
Post Office Box 2480 
Hollywood, FL 33022-2480 
Tel: (954) 925-1100 
Fax: (954) 925-1101 




Kerry P. Sisselman 
Reg. No, 37,237 
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